Information & Privacy
Protect confidential, personal, financial and business-critical information throughout its lifecycle while addressing relevant privacy risks.
:root{
–as-red:#8E231F;
–as-red-dark:#6E1714;
–as-red-soft:#F8ECEB;
–as-black:#221E1F;
–as-gray:#878787;
–as-text:#575252;
–as-off:#FAF8F7;
–as-line:#E7E1DF;
–as-white:#fff;
–as-ease:cubic-bezier(.22,1,.36,1)
}
#varutra-iso-27001{font-family:Inter,Arial,sans-serif;color:var(–as-black);background:#fff;line-height:1.7;overflow:hidden}
#varutra-iso-27001 *{box-sizing:border-box}
#varutra-iso-27001 img{max-width:100%;display:block}
#varutra-iso-27001 a{text-decoration:none}
#varutra-iso-27001 a:hover{text-decoration:none}
#varutra-iso-27001 button{font-family:inherit}
.as-container{width:min(1180px,calc(100% – 40px));margin:auto}
.as-section{padding:72px 0}
.as-section.alt{background:var(–as-off)}
.as-eyebrow{display:inline-flex;align-items:center;gap:9px;color:var(–as-red);font-size:12px;font-weight:800;letter-spacing:1.5px;text-transform:uppercase;margin-bottom:16px}
.as-eyebrow:before{content:””;width:28px;height:2px;background:var(–as-red)}
.as-title{font-size:clamp(32px,4vw,50px);line-height:1.08;letter-spacing:-1.7px;margin:0 0 18px;color:var(–as-black)}
.as-title em{font-style:normal;color:var(–as-red)}
.as-lead{font-size:17px;color:#555;max-width:800px}
.as-center{text-align:center}
.as-center .as-lead{margin:0 auto 15px}
.as-actions{display:flex;gap:12px;flex-wrap:wrap;margin-bottom:20px}
.as-btn{display:inline-flex;align-items:center;justify-content:center;gap:9px;min-height:50px;padding:0 22px;border-radius:8px;border:1px solid transparent;font-size:13px;font-weight:800;transition:.3s}
.as-btn.red{background:var(–as-red);color:#fff}
.as-btn.red:hover{background:var(–as-red-dark);transform:translateY(-2px)}
.as-btn.outline{background:#fff;border-color:#d4d0ce;color:var(–as-black)}
.as-btn.outline:hover{border-color:var(–as-red);color:var(–as-red)}
.as-hero{position:relative;min-height:750px;display:flex;align-items:center;background:#fff}
.as-hero:before{content:””;position:absolute;left:-260px;top:-250px;width:620px;height:620px;border:1px solid rgba(142,35,31,.10);border-radius:50%}
.as-hero:after{content:””;position:absolute;right:-260px;bottom:-360px;width:720px;height:720px;border:1px solid rgba(142,35,31,.12);border-radius:50%}
.as-hero-grid{display:grid;grid-template-columns:1.04fr .96fr;gap:65px;align-items:center;position:relative;z-index:1}
.as-kicker{margin-top:120px;display:inline-flex;align-items:center;gap:9px;background:var(–as-red-soft);color:var(–as-red);border-radius:50px;padding:8px 14px;font-size:12px;font-weight:800;margin-bottom:22px}
.as-hero h1{font-size:clamp(44px,4vw,70px);line-height:1.01;letter-spacing:-3px;margin:0 0 24px}
.as-hero h1 span{color:var(–as-red)}
.as-hero-copy>p{font-size:15px;color:#555;max-width:710px;margin:0 0 26px}
.as-service-links{display:flex;flex-wrap:wrap;gap:8px;margin:0 0 25px}
.as-service-link{display:inline-flex;align-items:center;padding:7px 11px;border:1px solid #ead4d2;border-radius:999px;background:#fff;color:var(–as-red);font-size:11px;font-weight:800;transition:.25s}
.as-service-link:hover{background:var(–as-red);color:#fff;border-color:var(–as-red);transform:translateY(-2px)}
.as-hero-visual{position:relative;min-height:520px}
.as-hero-image{position:absolute;inset:25px 0 0 0;overflow:hidden;background:#fff;border-radius:20px}
.as-hero-image img{margin-top:55px;width:100%;height:100%;object-fit:contain;object-position:center}
.as-cap-strip{background:#f7f5f4;border-top:1px solid var(–as-line);border-bottom:1px solid var(–as-line);padding:24px 0}
.as-cap-grid{display:flex;flex-wrap:nowrap;gap:12px;overflow-x:auto;overflow-y:hidden;padding:2px 2px 10px;-webkit-overflow-scrolling:touch;scroll-snap-type:x mandatory;scroll-behavior:smooth;scrollbar-width:none;overscroll-behavior-x:contain;touch-action:pan-y;cursor:grab}
.as-cap-grid::-webkit-scrollbar{display:none}
.as-cap-grid.is-dragging{cursor:grabbing;scroll-snap-type:none}
.as-cap{position:relative;flex:0 0 calc((100% – 36px)/4);min-height:145px;background:#fff;border:1px solid #e5e1df;border-radius:14px;padding:21px;scroll-snap-align:start;transition:.3s;overflow:hidden}
.as-cap:before{content:””;position:absolute;top:0;left:0;width:100%;height:3px;background:var(–as-red);transform:scaleX(0);transform-origin:left;transition:.3s}
.as-cap:hover{transform:translateY(-5px);border-color:rgba(142,35,31,.35);box-shadow:0 15px 35px rgba(34,30,31,.09)}
.as-cap:hover:before{transform:scaleX(1)}
.as-cap-num{position:absolute;top:16px;right:18px;font-size:10px;font-weight:800;color:#c9c3c1;letter-spacing:1px}
.as-cap-icon{width:42px;height:42px;border-radius:10px;background:var(–as-red-soft);color:var(–as-red);display:grid;place-items:center;margin-bottom:17px}
.as-cap h3{font-size:15px;margin:0 0 5px}
.as-cap p{font-size:11px;color:var(–as-gray);margin:0}
.as-overview-grid{display:grid;grid-template-columns:.72fr 1.28fr;gap:70px;align-items:start}
.as-big-number{font-size:clamp(80px,12vw,150px);line-height:.8;font-weight:800;letter-spacing:-8px;color:var(–as-red);opacity:.12;margin-bottom:10px}
.as-overview h2{font-size:clamp(32px,4vw,48px);line-height:1.1;margin:0 0 18px;letter-spacing:-1.5px}
.as-overview-copy p{font-size:16px;color:#666;margin:0 0 18px}
.as-compare{display:grid;grid-template-columns:1fr 1fr;border-top:1px solid var(–as-line);border-bottom:1px solid var(–as-line)}
.as-compare-card{padding:28px 26px}
.as-compare-card:first-child{border-right:1px solid var(–as-line)}
.as-compare-card h3{font-size:19px;margin:0 0 15px}
.as-list{list-style:none;display:grid;gap:10px;padding:0;margin:0}
.as-list li{display:flex;gap:10px;align-items:flex-start;font-size:14px;color:#666}
.as-list i{color:var(–as-red);margin-top:5px;font-size:11px}
.as-dark{background:var(–as-black);color:#fff;border-radius:40px}
.as-dark .as-title{color:#fff}
.as-dark .as-lead{color:#c9c2c1}
.as-risk-grid{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin-top:45px}
.as-risk-card{min-height:205px;padding:24px;border:1px solid rgba(255,255,255,.10);border-radius:14px;background:rgba(255,255,255,.035);transition:.3s}
.as-risk-card:hover{transform:translateY(-5px);border-color:rgba(142,35,31,.7);background:rgba(142,35,31,.10)}
.as-risk-icon{width:43px;height:43px;border-radius:10px;background:rgba(142,35,31,.18);color:#e5a09d;display:grid;place-items:center;margin-bottom:20px}
.as-risk-card h3{font-size:17px;margin:0 0 8px;color:#fff}
.as-risk-card p{font-size:13px;color:#afa9a9;margin:0}
.as-services-intro{max-width:860px;margin:0 auto 40px}
.as-tabs{scroll-margin-top:90px}
.as-tab-list{display:flex;flex-wrap:wrap;gap:10px;justify-content:center;list-style:none;margin:0 0 34px;padding:0}
.as-tab-btn{appearance:none;cursor:pointer;display:inline-flex;align-items:center;gap:8px;padding:11px 17px;border:1px solid var(–as-line);border-radius:999px;background:#fff;color:var(–as-black);font-size:13px;font-weight:750;line-height:1.35;transition:.25s}
.as-tab-btn:hover{border-color:var(–as-red);color:var(–as-red);transform:translateY(-2px);box-shadow:0 8px 18px rgba(34,30,31,.06)}
.as-tab-btn:focus-visible{outline:2px solid var(–as-red);outline-offset:2px}
.as-tab-btn[aria-selected=true]{background:var(–as-red);border-color:var(–as-red);color:#fff;box-shadow:0 12px 26px rgba(142,35,31,.28)}
.as-tab-panels{position:relative}
.as-tab-panel{display:none}
.as-tab-panel.active{display:block;animation:asFade .45s var(–as-ease) both}
@keyframes asFade{from{opacity:0;transform:translateY(14px)}to{opacity:1;transform:translateY(0)}}
.as-tab-inner{display:grid;grid-template-columns:.85fr 1.15fr;gap:44px;align-items:center;background:#fff;border:1px solid var(–as-line);border-radius:18px;padding:38px;box-shadow:0 20px 46px rgba(34,30,31,.06)}
.as-tab-media{position:relative;width:100%;aspect-ratio:1/1;overflow:hidden;border-radius:15px;background:#f7f5f4}
.as-tab-media img{position:absolute;inset:0;width:100%;height:100%;object-fit:cover}
.as-tab-body .num{display:inline-block;color:var(–as-red);background:var(–as-red-soft);padding:5px 12px;border-radius:999px;font-size:12.5px;margin-bottom:14px;font-weight:800}
.as-tab-body h3{font-size:26px;color:var(–as-black);margin:0 0 14px;line-height:1.25}
.as-tab-body p{font-size:15.5px;line-height:1.85;color:var(–as-text);margin:0 0 17px}
.as-tags{display:flex;flex-wrap:wrap;gap:8px}
.as-tag{background:#fff;color:var(–as-red);border:1px solid rgba(142,35,31,.18);padding:7px 12px;border-radius:999px;font-size:12px;font-weight:750}
#varutra-iso-27001 .as-method-shell{border:1px solid var(–as-line);border-radius:24px;background:#fff;box-shadow:0 18px 50px rgba(34,30,31,.08);padding:12px;overflow:hidden;margin-top:35px}
#varutra-iso-27001 .as-flow{display:flex;align-items:stretch;gap:8px;overflow-x:auto;scrollbar-width:thin;scrollbar-color:#d8d2d0 transparent;padding:4px}
#varutra-iso-27001 .as-flow-step{flex:1 1 0;min-width:155px;position:relative;cursor:pointer;padding:24px 20px;border-radius:17px;outline:none;transition:flex .45s var(–as-ease),background .3s ease,box-shadow .3s ease}
#varutra-iso-27001 .as-flow-step:hover,#varutra-iso-27001 .as-flow-step:focus-visible,#varutra-iso-27001 .as-flow-step.active{flex:2.6 1 0;background:var(–as-off);box-shadow:inset 0 0 0 1px rgba(142,35,31,.08)}
#varutra-iso-27001 .as-flow-step:focus-visible{box-shadow:inset 0 0 0 1px rgba(142,35,31,.18),0 0 0 3px rgba(142,35,31,.10)}
#varutra-iso-27001 .as-flow-icon{width:46px;height:46px;min-width:46px;border-radius:13px;display:flex;align-items:center;justify-content:center;background:var(–as-red-soft);color:var(–as-red);margin-bottom:14px;border:1px solid rgba(142,35,31,.08);transition:.3s}
#varutra-iso-27001 .as-flow-step:hover .as-flow-icon,#varutra-iso-27001 .as-flow-step:focus-visible .as-flow-icon,#varutra-iso-27001 .as-flow-step.active .as-flow-icon{background:var(–as-red);color:#fff;transform:translateY(-2px) scale(1.06);box-shadow:0 9px 20px rgba(142,35,31,.22)}
#varutra-iso-27001 .as-flow-num{display:inline-flex;align-items:center;justify-content:center;min-width:34px;height:24px;padding:0 9px;border-radius:999px;color:var(–as-red);background:var(–as-red-soft);border:1px solid rgba(142,35,31,.08);font-size:10px;font-weight:800;line-height:1;margin-bottom:11px}
#varutra-iso-27001 .as-flow-title{display:block;font-size:14px;font-weight:800;line-height:1.45;color:var(–as-black)}
#varutra-iso-27001 .as-flow-body{max-height:0;opacity:0;overflow:hidden;margin-top:0;transition:max-height .45s var(–as-ease),opacity .3s ease,margin-top .35s var(–as-ease)}
#varutra-iso-27001 .as-flow-step:hover .as-flow-body,#varutra-iso-27001 .as-flow-step:focus-visible .as-flow-body,#varutra-iso-27001 .as-flow-step.active .as-flow-body{max-height:430px;opacity:1;margin-top:12px}
#varutra-iso-27001 .as-flow-body p{font-size:13px;line-height:1.7;color:var(–as-text);margin:0 0 12px}
#varutra-iso-27001 .as-flow-body ul{margin:0;padding:0;list-style:none;display:grid;gap:7px}
#varutra-iso-27001 .as-flow-body li{display:flex;align-items:flex-start;gap:8px;font-size:12px;line-height:1.5;color:var(–as-text)}
#varutra-iso-27001 .as-flow-body li i{flex:0 0 auto;color:var(–as-red);font-size:10px;line-height:1.5;margin-top:2px}
.as-ref-grid{display:grid;grid-template-columns:repeat(6,1fr);gap:16px;margin-top:42px}
.as-ref-card{grid-column:span 2;padding:28px;background:#fff;border:1px solid var(–as-line);border-radius:18px;min-height:225px;transition:.3s}
.as-ref-card:nth-child(4){grid-column:2 / span 2}
.as-ref-card:nth-child(5){grid-column:4 / span 2}
.as-ref-card:hover{transform:translateY(-5px);box-shadow:0 18px 45px rgba(34,30,31,.08)}
.as-ref-code{font-size:11px;font-weight:800;letter-spacing:1.4px;color:var(–as-red);text-transform:uppercase}
.as-ref-card h3{font-size:21px;margin:13px 0 9px}
.as-ref-card p{font-size:13.5px;color:#666;margin:0 0 16px}
.as-text-link{color:var(–as-red);font-weight:800;font-size:13px}
.as-output-layout{display:grid;grid-template-columns:.85fr 1.15fr;gap:22px;margin-top:45px}
.as-output-intro{background:var(–as-black);color:#fff;border-radius:20px;padding:32px;position:relative;overflow:hidden}
.as-output-intro h3{font-size:25px;margin:0 0 12px;color:#fff}
.as-output-intro p{font-size:14px;color:#c5bebe}
.as-output-grid{display:grid;grid-template-columns:1fr 1fr;gap:12px}
.as-output-card{padding:20px;border:1px solid var(–as-line);border-radius:14px;background:#faf9f8}
.as-output-card span{display:block;color:var(–as-red);font-size:10px;font-weight:800;letter-spacing:1px;margin-bottom:10px}
.as-output-card h4{font-size:15px;margin:0 0 7px}
.as-output-card p{font-size:12.5px;color:#777;margin:0}
.as-why{background:#f7f5f4}
.as-why-top{display:grid;grid-template-columns:.85fr 1.15fr;gap:55px;align-items:end;margin-bottom:40px}
.as-why-top p{font-size:16px;color:#666;margin:0}
.as-why-grid{display:grid;grid-template-columns:repeat(3,1fr);border-top:1px solid #dcd7d5;border-bottom:1px solid #dcd7d5}
.as-why-card{padding:28px 22px;min-height:260px;border-bottom:1px solid #dcd7d5}
.as-why-card .num{font-size:12px;color:var(–as-red);font-weight:800;letter-spacing:1px}
.as-why-card h3{font-size:18px;line-height:1.3;margin:38px 0 12px}
.as-why-card p{font-size:13px;color:#777;margin:0}
.as-industry-grid{display:grid;grid-template-columns:repeat(4,1fr);gap:10px;margin-top:40px}
.as-industry{padding:20px 18px;border:1px solid var(–as-line);border-radius:12px;font-weight:800;font-size:14px;transition:.25s}
.as-industry:hover{background:var(–as-red);color:#fff;border-color:var(–as-red);transform:translateY(-3px)}
.as-industry small{display:block;font-size:10px;color:#999;font-weight:600;margin-top:4px}
.as-industry:hover small{color:#f1c8c5}
.as-compliance{background:#f7f5f4}
.as-compliance-box{margin-top:42px;border:1px solid var(–as-line);border-radius:18px;overflow:hidden;background:#fff}
.as-compliance-row{display:grid;grid-template-columns:220px 1fr;min-height:80px;border-bottom:1px solid var(–as-line)}
.as-compliance-row:last-child{border-bottom:0}
.as-compliance-name{padding:20px;background:#faf9f8;font-weight:800;color:var(–as-red);display:flex;align-items:center}
.as-compliance-text{padding:15px;font-size:13.5px;color:#666;display:flex;align-items:center}
.as-faq-list{max-width:900px;margin:42px auto 0;border-top:1px solid var(–as-line)}
.as-faq-item{border-bottom:1px solid var(–as-line)}
.as-faq-q{width:100%;background:none;border:0;padding:22px 0;text-align:left;font:800 16px Inter,Arial;color:var(–as-black);display:flex;justify-content:space-between;align-items:center;cursor:pointer}
.as-faq-q i{color:var(–as-red);transition:.25s}
.as-faq-q:focus-visible{outline:2px solid var(–as-red);outline-offset:4px}
.as-faq-a{display:grid;grid-template-rows:0fr;transition:.35s}
.as-faq-a>div{overflow:hidden}
.as-faq-a p{font-size:14px;color:#666;margin:0 40px 0 0;padding-bottom:0}
.as-faq-item.open .as-faq-a{grid-template-rows:1fr}
.as-faq-item.open .as-faq-a p{padding-bottom:22px}
.as-faq-item.open .as-faq-q i{transform:rotate(45deg)}
.as-final{padding:92px 0;background:var(–as-red);color:#fff;position:relative;overflow:hidden}
.as-final:before{content:””;position:absolute;width:550px;height:550px;border:1px solid rgba(255,255,255,.16);border-radius:50%;right:-220px;top:-270px}
.as-final .as-title{color:#fff;max-width:800px;margin:0 auto 15px}
.as-final .as-lead{color:#f2dedd;margin:0 auto 25px}
.as-final .as-actions{justify-content:center}
.as-final .as-btn.outline{background:transparent;border-color:rgba(255,255,255,.55);color:#fff}
.as-final .as-btn.outline:hover{background:var(–as-red);color:#fff;border-color:#fff}
.as-guide{padding-top:70px; padding-bottom:30px;}
.as-guide-box{background:linear-gradient(135deg,#221E1F,#3b2c2c);border-radius:22px;min-height:300px;padding:48px;color:#fff;display:grid;grid-template-columns:1.1fr .9fr;gap:30px;align-items:center;position:relative;overflow:hidden}
.as-guide-box h2{font-size:clamp(28px,4vw,45px);line-height:1.08;margin:0 0 13px;color:#fff}
.as-guide-box p{color:#c9c1c0;font-size:14px;margin:0 0 22px}
.as-guide-image{width:min(100%,310px);aspect-ratio:3/4;margin:auto;border-radius:16px;overflow:hidden;background:#fff;box-shadow:0 20px 45px rgba(0,0,0,.20)}
.as-guide-image img{width:100%;height:100%;object-fit:cover}
/* =========================================================
ISO 27001 WHITEPAPER DOWNLOAD
========================================================= */
#varutra-iso-27001 .as-whitepaper-box{
grid-template-columns:1.15fr .85fr;
min-height:390px;
background:
radial-gradient(circle at 85% 20%,rgba(142,35,31,.28),transparent 32%),
linear-gradient(135deg,#221E1F 0%,#302627 100%);
}
#varutra-iso-27001 .as-whitepaper-content{
position:relative;
z-index:2;
}
#varutra-iso-27001 .as-whitepaper-content .as-eyebrow{
margin-bottom:13px;
}
#varutra-iso-27001 .as-whitepaper-content h2{
max-width:680px;
font-size:clamp(32px,4vw,48px);
letter-spacing:-1.8px;
margin-bottom:10px;
}
#varutra-iso-27001 .as-whitepaper-lead{
color:#fff;
font-size:19px;
font-weight:700;
line-height:1.45;
margin-bottom:10px;
max-width:650px;
}
#varutra-iso-27001 .as-whitepaper-content > p:not(.as-whitepaper-lead){
max-width:680px;
color:#c9c1c0;
font-size:14px;
line-height:1.75;
margin-bottom:20px;
}
#varutra-iso-27001 .as-whitepaper-points{
display:flex;
flex-wrap:wrap;
gap:8px 18px;
margin:0 0 24px;
}
#varutra-iso-27001 .as-whitepaper-points span{
display:inline-flex;
align-items:center;
gap:7px;
color:#ddd6d5;
font-size:11.5px;
font-weight:600;
}
#varutra-iso-27001 .as-whitepaper-points i{
color:#e5a09d;
font-size:10px;
}
#varutra-iso-27001 .as-whitepaper-box .as-actions{
margin-bottom:13px;
}
#varutra-iso-27001 .as-whitepaper-box .as-btn.red{
background:#8E231F;
box-shadow:0 10px 25px rgba(0,0,0,.20);
}
#varutra-iso-27001 .as-whitepaper-box .as-btn.red:hover{
background:#a52b26;
transform:translateY(-3px);
}
#varutra-iso-27001 .as-whitepaper-note{
display:flex;
align-items:center;
gap:8px;
color:#958b89;
font-size:10.5px;
line-height:1.5;
}
#varutra-iso-27001 .as-whitepaper-note i{
color:#e5a09d;
}
#varutra-iso-27001 .as-whitepaper-image{
margin-top: 20px;
width:min(100%,300px);
aspect-ratio:3/4;
position:relative;
box-shadow:
0 25px 55px rgba(0,0,0,.35),
0 0 0 1px rgba(255,255,255,.12);
transition:transform .35s ease;
}
#varutra-iso-27001 .as-whitepaper-image img{
object-fit:cover;
}
#varutra-iso-27001 .as-paper-badge{
position:absolute;
z-index:3;
top:15px;
left:-16px;
display:flex;
align-items:center;
gap:7px;
padding:8px 13px;
background:#8E231F;
color:#fff;
font-size:9px;
font-weight:800;
letter-spacing:1px;
box-shadow:0 8px 20px rgba(0,0,0,.25);
}
#varutra-iso-27001 .as-paper-badge i{
font-size:11px;
}
/* Mobile */
@media(max-width:1000px){
#varutra-iso-27001 .as-whitepaper-box{
grid-template-columns:1fr;
}
#varutra-iso-27001 .as-whitepaper-image{
order:-1;
}
}
@media(max-width:760px){
#varutra-iso-27001 .as-whitepaper-box{
padding:25px 19px 28px;
gap:27px;
}
#varutra-iso-27001 .as-whitepaper-content h2{
font-size:30px;
line-height:1.1;
}
#varutra-iso-27001 .as-whitepaper-lead{
font-size:16px;
}
#varutra-iso-27001 .as-whitepaper-points{
display:grid;
grid-template-columns:1fr;
gap:8px;
margin-bottom:21px;
}
#varutra-iso-27001 .as-whitepaper-box .as-actions{
flex-direction:column;
}
#varutra-iso-27001 .as-whitepaper-box .as-btn{
width:100%;
}
#varutra-iso-27001 .as-whitepaper-image{
width:min(100%,220px);
}
}
@media(max-width:1000px){
.as-hero-grid,.as-overview-grid,.as-output-layout,.as-guide-box,.as-why-top{grid-template-columns:1fr}
.as-hero{min-height:auto;padding:75px 0}
.as-hero-visual{min-height:420px}
.as-cap-grid{
gap:12px;
padding:4px 2px 12px;
}
.as-cap{
flex:0 0 270px;
}
.as-risk-grid{grid-template-columns:repeat(2,1fr)}
.as-why-grid{grid-template-columns:repeat(2,1fr)}
.as-industry-grid{grid-template-columns:repeat(2,1fr)}
.as-ref-grid{grid-template-columns:1fr 1fr}
.as-ref-card,.as-ref-card:nth-child(4),.as-ref-card:nth-child(5){grid-column:auto}
}
@media(max-width:760px){
#varutra-iso-27001{width:100%;max-width:100%;overflow-x:hidden}
.as-container{width:calc(100% – 28px);max-width:100%}
.as-section{padding:54px 0}
.as-title{font-size:clamp(28px,8vw,38px);line-height:1.1;letter-spacing:-1.15px}
.as-lead{font-size:15px;line-height:1.7}
.as-eyebrow{font-size:10.5px;letter-spacing:1.2px;gap:7px;margin-bottom:13px}
.as-hero{padding:42px 0 34px}
.as-hero-grid{grid-template-columns:1fr;gap:26px}
.as-kicker{margin-top:0;margin-bottom:16px;padding:7px 12px;font-size:10.5px}
.as-hero h1{font-size:clamp(34px,10vw,44px);line-height:1.04;letter-spacing:-1.9px;margin-bottom:18px}
.as-hero-copy>p{font-size:15.5px;line-height:1.72;margin-bottom:20px}
.as-service-links{gap:7px;margin-bottom:21px}
.as-service-link{padding:7px 10px;font-size:10px}
.as-actions{width:100%;flex-direction:column;gap:9px;margin-bottom:0}
.as-actions .as-btn{width:100%;min-height:48px;padding:10px 15px;text-align:center}
.as-hero-visual{min-height:250px}
.as-hero-image{inset:0;border-radius:18px}
.as-hero-image img{object-fit:contain}
.as-cap-strip{
padding:14px 0;
overflow:hidden;
}
.as-cap-grid{
gap:9px;
padding:3px 2px 10px;
}
.as-cap{
flex:0 0 78%;
min-height:145px;
padding:15px 13px;
border-radius:12px;
}
.as-cap-icon{
width:36px;
height:36px;
margin-bottom:12px;
border-radius:9px;
}
.as-cap h3{
font-size:12px;
line-height:1.35;
}
.as-cap p{
font-size:9.5px;
line-height:1.5;
}
.as-overview-grid{grid-template-columns:1fr;gap:20px}
.as-big-number{font-size:82px;letter-spacing:-5px}
.as-overview h2{font-size:clamp(28px,8vw,38px)}
.as-overview-copy p{font-size:14.5px;line-height:1.72}
.as-compare{grid-template-columns:1fr}
.as-compare-card{padding:21px 17px}
.as-compare-card:first-child{border-right:0;border-bottom:1px solid var(–as-line)}
.as-list li{font-size:13px;line-height:1.55}
.as-dark{border-radius:24px}
.as-risk-grid{grid-template-columns:1fr;gap:10px;margin-top:28px}
.as-risk-card{min-height:auto;padding:19px 17px;border-radius:13px}
.as-risk-card h3{font-size:16px}
.as-risk-card p{font-size:12.5px;line-height:1.65}
.as-tab-list{justify-content:flex-start;flex-wrap:nowrap;overflow-x:auto;overflow-y:hidden;-webkit-overflow-scrolling:touch;scroll-snap-type:x proximity;scrollbar-width:none;gap:7px;padding:3px 2px 10px;margin-bottom:18px}
.as-tab-list::-webkit-scrollbar{display:none}
.as-tab-list li{flex:0 0 auto;scroll-snap-align:start}
.as-tab-btn{min-height:42px;padding:9px 13px;font-size:11px;white-space:nowrap}
.as-tab-inner{grid-template-columns:1fr;gap:20px;padding:17px;border-radius:15px}
.as-tab-media{aspect-ratio:4/3;border-radius:12px}
.as-tab-body h3{font-size:22px}
.as-tab-body p{font-size:14px;line-height:1.72}
#varutra-iso-27001 .as-method-shell{padding:7px;border-radius:17px}
#varutra-iso-27001 .as-flow{display:block;overflow:visible;padding:0}
#varutra-iso-27001 .as-flow-step,
#varutra-iso-27001 .as-flow-step.active,
#varutra-iso-27001 .as-flow-step:hover,
#varutra-iso-27001 .as-flow-step:focus-visible{display:block;width:100%;min-width:0;flex:none;padding:16px 15px;margin:0 0 7px;border-radius:13px;background:#fff;box-shadow:none}
#varutra-iso-27001 .as-flow-step.active{background:var(–as-off);box-shadow:inset 0 0 0 1px rgba(142,35,31,.08)}
#varutra-iso-27001 .as-flow-body,
#varutra-iso-27001 .as-flow-step:hover .as-flow-body,
#varutra-iso-27001 .as-flow-step:focus-visible .as-flow-body{max-height:0;opacity:0;margin-top:0;overflow:hidden}
#varutra-iso-27001 .as-flow-step.active .as-flow-body{max-height:900px;opacity:1;margin-top:10px}
#varutra-iso-27001 .as-flow-title{font-size:13px}
.as-ref-grid{grid-template-columns:1fr;gap:10px;margin-top:28px}
.as-ref-card,.as-ref-card:nth-child(4),.as-ref-card:nth-child(5){grid-column:auto;min-height:0;padding:21px 18px}
.as-output-layout{grid-template-columns:1fr;gap:12px;margin-top:28px}
.as-output-intro{padding:23px 19px;border-radius:16px}
.as-output-grid{grid-template-columns:1fr;gap:9px}
.as-why-top{grid-template-columns:1fr;gap:12px;margin-bottom:25px}
.as-why-top p{font-size:14px}
.as-why-grid{grid-template-columns:1fr}
.as-why-card{min-height:0;padding:22px 17px;border-right:0;border-bottom:1px solid #dcd7d5}
.as-why-card h3{font-size:17px;margin:20px 0 9px}
.as-industry-grid{grid-template-columns:1fr;gap:8px;margin-top:27px}
.as-industry{padding:16px 15px;font-size:13px}
.as-compliance-box{margin-top:28px;border-radius:14px}
.as-compliance-row{grid-template-columns:1fr;min-height:0}
.as-compliance-name{padding:13px 15px 7px}
.as-compliance-text{padding:5px 15px 14px;font-size:12.5px;line-height:1.65}
.as-faq-list{margin-top:28px}
.as-faq-q{padding:18px 0;gap:14px;font-size:14px;line-height:1.45}
.as-faq-a p{font-size:13px;line-height:1.7;margin-right:0}
.as-final{padding:58px 0}
.as-final .as-title{max-width:none}
.as-guide{padding:52px 0}
.as-guide-box{grid-template-columns:1fr;gap:24px;min-height:0;padding:25px 19px;border-radius:17px}
.as-guide-box h2{font-size:30px}
.as-guide-box p{font-size:13px;line-height:1.65}
.as-guide-image{width:min(100%,250px)}
#varutra-iso-27001 h1,#varutra-iso-27001 h2,#varutra-iso-27001 h3,#varutra-iso-27001 h4,#varutra-iso-27001 p,#varutra-iso-27001 a,#varutra-iso-27001 li,#varutra-iso-27001 span{overflow-wrap:anywhere}
}
@media(max-width:480px){
.as-container{width:calc(100% – 24px)}
.as-section{padding:48px 0}
.as-hero{padding-top:34px}
.as-hero h1{font-size:35px}
.as-hero-visual{min-height:215px}
.as-cap{min-height:0;display:grid;grid-template-columns:38px 1fr;column-gap:12px;align-items:center;padding:14px}
.as-cap-icon{grid-row:1 / span 2;margin:0}
.as-cap h3{margin:0 0 2px;padding-right:20px}
.as-tab-inner{padding:14px}
.as-tab-media{aspect-ratio:16/10}
.as-tab-body h3{font-size:20px}
.as-final{padding:50px 0}
}
@media(prefers-reduced-motion:reduce){
#varutra-iso-27001 *{animation-duration:.001ms;transition-duration:.001ms;scroll-behavior:auto}
}
/* ———- ISO 27001 Readiness Assessment: same modal system as DPDP assessment ———- */
#open{background:var(–as-red);color:#fff;border:0;padding:14px 24px;border-radius:10px;font-weight:700}
.modal *{font-family:inherit;}
.modal{
position:fixed ;
inset:0 ;
display:none ;
justify-content:center ;
align-items:center ;
padding:24px ;
background:rgba(0,0,0,.65) ;
backdrop-filter:blur(6px) ;
z-index:99999999 ;
}
.modal.show{display:flex ;}
.card{
width:min(780px,95vw) ;
max-height:80vh ;
overflow-y:auto ;
background:#fff ;
border-radius:18px ;
margin:120px auto 10px auto ;
box-shadow:0 25px 70px rgba(0,0,0,.30) ;
z-index:999999999 ;
}
.header{
padding:16px 24px 12px ;
background:var(–as-black) ;
color:#fff ;
position:relative;
}
.close-modal{
position:absolute; top:14px; right:18px;
background:transparent ; border:none ; outline:none;
padding:0; margin:0; width:auto; height:auto;
color:#fff; font-size:34px; font-weight:300; line-height:1;
cursor:pointer; transition:color .25s ease,transform .25s ease;
box-shadow:none ; z-index:1000;
}
.close-modal:hover{background:transparent ;color:#ff8a80;transform:scale(1.15);}
.close-modal:focus{outline:none;background:transparent ;}
.progress{height:8px;background:#eee}
.bar{height:8px;background:var(–as-red);width:6.25%;transition:.3s}
.content{padding:28px ;}
.q{display:none}
.q.active{display:block}
.opt{
display:flex ; align-items:center ; gap:12px ;
width:100% ; padding:6px 20px ; margin:14px 0 ;
border:1px solid #ddd ; border-radius:12px ; transition:.2s ;
}
.opt:hover{border-color:var(–as-red) ;background:#faf7f7 ;}
.iso-assessment-category{
margin-bottom:20px;
display:inline-block;color:var(–as-red);background:var(–as-red-soft);
padding:6px 11px;border-radius:999px;font-size:11px;font-weight:800;
letter-spacing:.35px;
}
.wpcf7-submit{
width:100% ;
height:54px ;
background:#ffffff ;
color:#8E231F ;
border:2px solid #8E231F ;
border-radius:10px ;
font-size:16px ;
font-weight:600 ;
cursor:pointer ;
transition:.25s ease ;
display:block ;
visibility:visible ;
opacity:1 ;
margin-top:20px ;
}
.wpcf7-submit:hover{
background:#8E231F ;
color:#ffffff ;
border-color:#8E231F ;
}
/* =========================================================
ISO 27001 WHITEPAPER DOWNLOAD MODAL
Same modal styling/positioning as the DPDP whitepaper form
========================================================= */
.whitepaper-modal *{
font-family:inherit;
}
.whitepaper-modal{
position:fixed ;
inset:0 ;
display:none ;
justify-content:center ;
align-items:center ;
padding:24px ;
background:rgba(0,0,0,.65) ;
backdrop-filter:blur(6px) ;
z-index:99999999 ;
}
.whitepaper-modal.show{
display:flex ;
}
/* Keep the whitepaper popup card identical to the DPDP card */
.whitepaper-modal .card{
width:min(780px,95vw) ;
max-height:80vh ;
overflow-y:auto ;
background:#fff ;
border-radius:18px ;
margin:120px auto 10px auto ;
box-shadow:0 25px 70px rgba(0,0,0,.30) ;
z-index:999999999 ;
}
.whitepaper-modal .header{
padding:16px 24px 12px ;
background:var(–as-black) ;
color:#fff ;
position:relative;
}
.whitepaper-modal .close-modal{
position:absolute;
top:14px;
right:18px;
background:transparent ;
border:none ;
outline:none;
padding:0;
margin:0;
width:auto;
height:auto;
color:#fff;
font-size:34px;
font-weight:300;
line-height:1;
cursor:pointer;
transition:color .25s ease,
transform .25s ease;
box-shadow:none ;
z-index:1000;
}
.whitepaper-modal .close-modal:hover{
background:transparent ;
color:#ff8a80;
transform:scale(1.15);
}
.whitepaper-modal .close-modal:focus{
outline:none;
background:transparent ;
}
.whitepaper-modal .content{
padding:28px ;
}
/* Match DPDP whitepaper CF7 input appearance */
.whitepaper-modal input[type=text],
.whitepaper-modal input[type=email],
.whitepaper-modal input[type=tel]{
width:100%;
padding:12px;
margin:8px 0 18px;
border:1px solid #ccc;
border-radius:8px;
}
/* Match DPDP whitepaper CF7 submit button */
.whitepaper-modal .wpcf7-submit{
width:100% ;
height:54px ;
background:#ffffff ;
color:#8E231F ;
border:2px solid #8E231F ;
border-radius:10px ;
font-size:16px ;
font-weight:600 ;
cursor:pointer ;
transition:.25s ease ;
display:block ;
visibility:visible ;
opacity:1 ;
margin-top:20px ;
}
.whitepaper-modal .wpcf7-submit:hover{
background:#8E231F ;
color:#ffffff ;
border-color:#8E231F ;
}
.footer{
display:flex;justify-content:space-between;padding-top:0;padding-right:28px;
padding-bottom:22px;padding-left:28px;background:#fafafa;
}
.nav{background:var(–as-red);color:#fff;border:0;padding:12px 20px;border-radius:8px}
.prev{background:#777}
.final{display:none}
.final-actions{display:flex;justify-content:space-between;gap:12px;margin-top:24px;}
.final-actions .prev{background:#777}
.final-actions .nav{min-width:170px}
Build, implement and improve an Information Security Management System (ISMS) with a practical, risk-based approach. Varutra supports organizations across India with ISO/IEC 27001:2022 gap assessment, risk assessment, ISMS design and documentation, control implementation, training and awareness, internal audit and certification readiness.
Identify ISMS, control and evidence gaps against ISO/IEC 27001:2022.
Identify and evaluate information-security risks within the ISMS scope.
Implement risk-based security controls aligned with the ISMS and Annex A.
Prioritize and address remaining gaps to strengthen ISO 27001 readiness.
Develop policies, procedures, registers, SoA and supporting evidence.
Prepare controls, evidence and teams for independent certification audits.
Use a structured implementation roadmap to understand scope,
risk assessment, policies, controls, evidence, internal audit
and certification readiness before starting your project.
ISO/IEC 27001:2022 is an international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It gives organizations a structured way to understand information-security risks, select appropriate controls and demonstrate that security is governed as an ongoing management process.
ISO/IEC 27001:2022 is not simply a checklist of technical controls. An effective ISMS connects leadership, people, processes, technology, risk management, documentation, evidence and continual improvement. The applicable Annex A controls are selected based on the organization’s risk treatment and documented through the Statement of Applicability.
An ISO/IEC 27001:2022 ISMS provides a risk-based framework to manage information security, cybersecurity and privacy-related risks across people, processes, technology and third parties.
Protect confidential, personal, financial and business-critical information throughout its lifecycle while addressing relevant privacy risks.
Identify and treat cybersecurity risks affecting systems, networks, applications, endpoints and information assets.
Manage authentication, authorization, privileged access and access governance to reduce unauthorized access risks.
Address security risks across cloud services, infrastructure, applications, networks, endpoints and technology operations.
Manage security responsibilities, awareness and risks arising from employees, suppliers, vendors, partners and outsourced services.
Strengthen incident response, backup, recovery, availability and business continuity as part of a resilient ISMS.
Our ISO 27001 approach takes organizations from understanding their
current information-security posture to establishing, operating and
independently assessing an effective Information Security Management
System (ISMS).
01 / 07
Identify compliance gaps and establish a clear path to ISO 27001 readiness.
We assess your existing information security governance, processes,
controls, documentation and evidence against applicable
ISO/IEC 27001:2022 requirements.
We map identified gaps to the relevant ISMS requirements and Annex A
controls, prioritize remediation needs and develop a practical roadmap
to strengthen your information security management system and
certification readiness.
02 / 07
Establish a risk-based foundation for your ISMS.
We help identify information-security risks within the defined
ISMS scope, evaluate their potential impact and likelihood,
and establish appropriate risk treatment decisions.
The process can cover assets and information, threats,
vulnerabilities, existing controls, business impact, risk
criteria, risk ownership, treatment actions and residual risk.
The results provide the basis for control selection and the
Statement of Applicability.
03 / 07
Design an ISMS that reflects your organization’s scope,
risks and operating environment.
We help establish the governance framework and documented process
required to manage information security systematically.
Depending on the organization’s scope and requirements, this
can include ISMS scope definition, Information Security Policy,
supporting policies and procedures, risk assessment
methodology, Risk Treatment Plan, Statement of Applicability,
objectives, roles and responsibilities, control documentation
and evidence requirements.
04 / 07
Turn the documented ISMS into an operating management system.
We work with stakeholders and control owners to implement
applicable information-security processes, controls,
responsibilities and evidence mechanisms.
Implementation may address areas such as access management,
asset management, information classification, supplier
security, incident management, vulnerability management,
logging and monitoring, business continuity, physical security
and other controls determined by the organization’s risk
assessment and Statement of Applicability.
05 / 07
Embed information-security responsibilities across the
organization.
We provide awareness and role-based training to help employees,
managers and control owners understand their responsibilities
within the ISMS.
Training can cover information-security policies, acceptable
use, secure information handling, incident reporting, access
security, security responsibilities, audit evidence
expectations and role-specific control requirements. Awareness
activities can be aligned with organizational roles and the
defined ISMS scope.
06 / 07
Validate the ISMS before the independent certification audit.
We assess whether the implemented ISMS conforms to applicable
ISO/IEC 27001 requirements and whether relevant processes and
controls are operating as intended.
Internal audit activities can include audit planning,
interviews, document and evidence review, control testing,
process verification, finding identification,
nonconformity reporting and corrective-action tracking.
Management review preparation can also be supported where
required.
07 / 07
Prepare your organization for independent ISO 27001
certification.
We help bring together the ISMS documentation, risk treatment,
controls, responsibilities and evidence required for the
external certification assessment.
Support can include Stage 1 documentation-readiness
preparation, Stage 2 implementation-readiness preparation,
evidence coordination, audit preparation, finding analysis and
corrective-action planning. The ISO 27001 certificate itself
is issued by the independent certification body.
ISO/IEC 27001:2022 is the requirements standard for an ISMS. Supporting standards and frameworks can provide additional guidance depending on your objectives, scope and risk environment.
Defines requirements for establishing, implementing, maintaining and continually improving an Information Security Management System.
Provides a reference set of information-security controls and implementation guidance that can support control design and improvement.
Supports information-security risk management and can inform risk identification, analysis, treatment and monitoring activities.
Deliverables are tailored to the agreed ISMS scope and maturity. The objective is to create a working management system-not just documentation that exists only for the audit.
We translate ISO/IEC 27001:2022 requirements into defined risks, controls,
responsibilities and documented evidence-helping your teams implement,
operate and continually improve the ISMS.
Current-state findings, evidence observations and prioritized remediation actions.
Documented information-security risks, treatment decisions, owners and status.
Scope-relevant governance documents, policies and operating procedures.
Traceability for applicable controls, implementation status and rationale.
Audit observations, conformity findings, nonconformities and corrective actions.
Evidence coordination and readiness support for the independent certification audit.
Varutra combines information-security consulting, cybersecurity assessment
and GRC expertise to connect ISO 27001 requirements with your technical
and operational environment. Our Audit & Compliance practice supports
ISO 27001 implementation, gap assessment, risk assessment, internal audit,
training, documentation and ongoing ISMS improvement.
Translate business and information-security risks into treatment decisions,
control ownership and practical ISO 27001 implementation priorities.
Connect ISO 27001 governance with vulnerability management, application
security, infrastructure security and security operations.
Build operating processes, responsibilities, evidence and review practices
that help the ISMS remain effective and continually improve after certification.
Prepare documentation, evidence, control owners and corrective actions
for the independent ISO 27001 certification assessment.
Where applicable, align ISO 27001 security governance with Indian regulatory,
contractual, customer and sector-specific security requirements.
Work with experienced cybersecurity, information-security and GRC professionals
supporting ISO 27001 implementation, assessment, audit readiness and compliance.
ISO 27001 can provide an information-security governance foundation that may support customer, contractual, regulatory and assurance requirements. Exact applicability depends on your organization, sector, data and scope.
Answers to common questions about ISO 27001 certification, consulting, ISMS implementation, risk assessment, internal audit and certification readiness in India.
ISO/IEC 27001:2022 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It provides a risk-based management framework for protecting information and managing information-security risks.
ISO 27001 certification means an independent certification body has audited an organization’s ISMS against the applicable ISO/IEC 27001 requirements and determined that it conforms to the certification criteria. Consultants can prepare and support the organization, but the certificate is issued by the independent certification body.
ISO 27001 consulting can include ISMS scoping, gap assessment, risk assessment, risk treatment planning, Statement of Applicability support, policy and procedure development, control implementation, training and awareness, internal audit, management review readiness, corrective-action support and certification audit preparation.
An ISO 27001 gap assessment compares an organization’s current information-security governance, processes, controls and evidence against the applicable ISO/IEC 27001:2022 requirements. The outcome typically includes identified gaps, risk or priority context, evidence observations and a practical remediation roadmap.
Risk assessment and risk treatment are core parts of an ISO/IEC 27001 ISMS. Organizations determine which information-security risks require treatment and select appropriate controls. The Statement of Applicability documents the selected controls, their applicability and implementation status, including the rationale for exclusions where applicable.
The timeline varies with the ISMS scope, organization size, number of locations, existing controls, documentation maturity, risk profile and audit readiness. A focused organization with an established security program may progress faster than an organization building its ISMS from the ground up. Certification-body scheduling is also a separate factor.
ISO 27001 certification cost depends on ISMS scope, organization size, locations, technology environment, existing security maturity, consulting effort and certification-body audit fees. Consulting and certification-body fees are separate cost components, so a scope-based assessment is more accurate than a generic fixed price.
Get a clear view of your ISO/IEC 27001:2022 readiness, information-security risks, documentation gaps and implementation priorities with support from Varutra’s cybersecurity and GRC team in India.
We respect your privacy. Your information will be kept confidential and handled securely.
We have not started ISO 27001 implementation
We have started implementation, but several areas are still being developed
Our ISMS is largely established and we are preparing for certification
We are already ISO 27001 certified and are working on maintaining/improving the ISMS
No — the ISMS scope has not yet been defined
Partially — we have a proposed scope, but it is still being finalized
Yes — the ISMS scope is formally defined and documented
No — these have not been formally identified
Partially — some business operations, departments, processes, locations or assets are identified
Yes — relevant business operations, departments, processes, locations and information assets are documented
No — formal information security policies/procedures are not established
Partially — some policies/procedures exist but require development or updating
Yes — policies and procedures are documented, approved and maintained
No — a formal information security risk assessment has not been conducted
Partially — a risk assessment has been conducted, but it is not yet established as a regular process
Yes — risk assessments are conducted periodically using a defined methodology
No — risks have been identified, but formal treatment/controls have not been established
Partially — some risks have been treated and controls implemented
Yes — risks are formally treated and relevant security controls are implemented and monitored
No — information security responsibilities, governance or third-party requirements are not formally defined
Partially — some responsibilities, governance processes or third-party requirements are defined
Yes — information security responsibilities, governance and third-party security requirements are formally defined and maintained
No — third-party and outsourced service risks are not formally assessed or managed
Partially — some key vendors, outsourced services or external IT providers are assessed
Yes — third-party security requirements, assessments and risks are formally managed
No — formal continuity/recovery arrangements are not established
Partially — arrangements exist but are not fully documented or tested
Yes — continuity, backup/recovery and disaster recovery arrangements are documented and periodically tested
No — formal information security awareness, training or responsibilities are not established
Partially — training or security responsibilities are addressed for some employees or periodically
Yes — security responsibilities, awareness and training are formally established and regularly maintained
No — physical security measures are not formally established
Partially — some physical security measures are implemented, but gaps remain
Yes — physical access, secure areas, equipment protection and secure disposal measures are formally implemented and maintained
No — key technical security controls are not formally implemented
Partially — technical controls are implemented in some systems or areas, but gaps remain
Yes — technical security controls are implemented, monitored and regularly reviewed
No — VAPT/security testing has not been conducted
Previously — testing has been conducted, but not recently or regularly
Yes — security testing is conducted periodically and findings are addressed
No — an ISMS internal audit has not yet been conducted
Partially — an internal audit has been conducted, but the process is not yet established
Yes — internal audits are conducted periodically and findings are tracked
No — management review and formal corrective-action tracking are not established
Partially — reviews/actions happen, but the process is not yet formalized
Yes — management reviews the ISMS and corrective actions are formally tracked to closure
No — critical applications, IT systems, security tools and the IT environment have not been formally identified
Partially — some applications, systems, security tools or IT infrastructure are identified
Yes — relevant applications, systems, security tools and IT infrastructure are documented and managed within the ISMS scope
Please provide your details to receive your personalized ISO 27001 readiness assessment.
1-1011-5051-200201-500501-10001000+
We respect your privacy. Your information will be kept confidential and handled securely.